🔐 CVE Alert

CVE-2026-93538

HIGH 7.1

Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.

CWE CWE-290 CWE-639
Vendor suse
Product rancher
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for suse rancher

Be the first to know when new high vulnerabilities affecting suse rancher are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

SUSE / Rancher
0.16.0 < 0.16.1 0.15.0 < 0.15.6 0.14.0 < 0.14.10 0.13.0 < 0.13.15 0.12.0 < 0.12.19

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/rancher/fleet/security/advisories/GHSA-h9p5-fp5h-qpqr

Credits

https://github.com/Pig-Tail